LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-27-2011, 02:51 AM   #31
qwertyjjj
Senior Member
 
Registered: Jul 2009
Location: UK
Distribution: Cent OS5 with Plesk
Posts: 1,013

Original Poster
Rep: Reputation: 30

Quote:
Originally Posted by nomb View Post
Seriously? Hack web app, get system access as Apache user, use local privilege escalation to get root...
PHP runs with safe mode so there is no way to run system commands through the web app.
 
Old 04-27-2011, 04:26 AM   #32
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Quote:
PHP runs with safe mode so there is no way to run system commands through the web app.
How many systems have been compromised in a manner that wasn't supposed to be possible?
How many zero day exploits have been found after a vulnerability had been in the code for years?
Here at LQ security we have even been on the forefront, investigating previously unknown vulnerabilities. Take the recent Exim privilege elevation vulnerability for example.

Running things like PHP safe mode and Mod Security do help, but they are certainly not impregnable. It is foolish to think otherwise.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to compare two columns in a file. shilpa.godhe Linux - Newbie 2 03-29-2010 02:42 AM
Script to compare file size nazs Programming 6 05-24-2006 10:10 AM
mass file compare or diff mijohnst Linux - Software 11 01-27-2006 06:32 AM
php read from file and compare. xushi Programming 11 07-14-2005 01:10 PM
file compare program Nyc0n Linux - General 4 08-18-2001 09:08 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:53 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration